HIGH
XSS in platform
Published Oct 19, 2020
8.0
HIGHCVSS 3.1
EPSS 0.75%
Description
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.
Affected products
-
Affected
- ≥ 9.0.0, < 9.4.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Orchidsoftware | Platform | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1411 Advisory
- https://github.com/advisories/GHSA-589w-hccm-265x Advisory
- https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169 x_refsource_MISCPatchThird Party Advisory
- https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-15263
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1411 | Advisory | |
| https://github.com/advisories/GHSA-589w-hccm-265x | Advisory | |
| https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-15263 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 19, 2020
Updated Aug 4, 2024
Reserved Jun 25, 2020
Link CVE-2020-15263
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-589W-HCCM-265X